CVE-2026-5707 is a command injection vulnerability in AWS Research and Engineering Studio (RES) affecting versions 2025.03 through 2025.12.01. The flaw exists in the virtual desktop session name handling functionality where unsanitized user input is passed to OS commands, potentially allowing execution of arbitrary code with root privileges on the virtual desktop host. The vulnerability presents a HIGH severity risk with a CVSS score of 8.8, exploitable remotely over the network by authenticated users with minimal complexity and no user interaction required. The attack grants full confidentiality, integrity, and availability impact to the affected system. While the EPSS score of 0.0011 indicates lower relative exploit probability compared to other CVEs, the high privilege level of potential compromise warrants immediate attention. There is currently no evidence of active exploitation in the wild, and the vulnerability does not appear on the CISA Known Exploited Vulnerabilities catalog or active threat intelligence hotlists. Mitigation is available through upgrade to RES version 2026.03 or application of a corresponding patch to existing installations. Organizations using affected RES versions should prioritize remediation given the ease of exploitation by authenticated users and severe impact potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.03CPE matchmatch criteria | cpe:2.3:a:amazon:research_and_engineering_studio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.